Totolink T8 Firmware vulnerabilities
26 known vulnerabilities affecting totolink/t8_firmware.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH8MEDIUM1
Vulnerabilities
Page 2 of 2
CVE-2024-46419P3CRITICALCVSS 9.8v4.1.5cu.861_b202302202024-09-16
CVE-2024-46419 [CRITICAL] CWE-120 CVE-2024-46419: TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg fu
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.
nvd
CVE-2024-8580P3HIGHCVSS 8.1v4.1.5cu.861_b202302202024-09-08
CVE-2024-8580 [HIGH] CWE-259 CVE-2024-8580: A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This v
A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit
nvd
CVE-2024-0569P3CRITICALCVSS 9.1v4.1.5cu.833_202209052024-01-16
CVE-2024-0569 [CRITICAL] CWE-200 CVE-2024-0569: A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This a
A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument ssid/key leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disc
nvd
CVE-2023-24155P3CRITICALCVSS 9.8vv4.1.5cu2023-02-03
CVE-2023-24155 [CRITICAL] CWE-798 CVE-2023-24155: TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is
TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.
nvd
CVE-2024-46424P4HIGHCVSS 7.5v4.1.5cu.861_b202302202024-09-16
CVE-2024-46424 [HIGH] CWE-120 CVE-2024-46424: TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomMod
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter.
nvd
CVE-2024-0944P4MEDIUMCVSS 5.3v4.1.5cu.833_202209052024-01-26
CVE-2024-0944 [MEDIUM] CWE-613 CVE-2024-0944: A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Aff
A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult.
nvd
← Previous2 / 2